Vulnerabilities (CVE)

Filtered by CWE-434
Total 4401 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2021-46036 1 Mingsoft 1 Mcms 2026-06-17 7.5 HIGH 9.8 CRITICAL
An arbitrary file upload vulnerability in the component /ms/file/uploadTemplate.do of MCMS v5.2.4 allows attackers to execute arbitrary code.
CVE-2021-46033 1 Forestblog Project 1 Forestblog 2026-06-17 7.5 HIGH 9.8 CRITICAL
In ForestBlog, as of 2021-12-28, File upload can bypass verification.
CVE-2021-46013 1 Free School Management Software Project 1 Free School Management Software 2026-06-17 7.5 HIGH 9.8 CRITICAL
An unrestricted file upload vulnerability exists in Sourcecodester Free school management software 1.0. An attacker can leverage this vulnerability to enable remote code execution on the affected web server. Once a php webshell containing "<?php system($_GET["cmd"]); ?>" gets uploaded it is saved into /uploads/exam_question/ directory, and is accessible by all users.
CVE-2021-45982 1 Netscout 1 Ngeniusone 2026-06-17 6.5 MEDIUM 8.8 HIGH
NetScout nGeniusONE 6.3.2 allows Arbitrary File Upload by a privileged user.
CVE-2021-45865 1 Student Attendance Management System Project 1 Student Attendance Management System 2026-06-17 7.5 HIGH 9.8 CRITICAL
A File Upload vulnerability exists in Sourcecodester Student Attendance Manageent System 1.0 via the file upload functionality.
CVE-2021-45835 1 Online Admission System Project 1 Online Admissions System 2026-06-17 7.5 HIGH 9.8 CRITICAL
The Online Admission System 1.0 allows an unauthenticated attacker to upload or transfer files of dangerous types to the application through documents.php, which may be used to execute malicious code or lead to code execution.
CVE-2021-45790 1 Metersphere 1 Metersphere 2026-06-17 N/A 9.8 CRITICAL
An arbitrary file upload vulnerability was found in Metersphere v1.15.4. Unauthenticated users can upload any file to arbitrary directory, where attackers can write a cron job to execute commands.
CVE-2021-45411 1 Printable Staff Id Card Creator System Project 1 Printable Staff Id Card Creator System 2026-06-17 7.5 HIGH 9.8 CRITICAL
In Sourcecodetester Printable Staff ID Card Creator System 1.0 after compromising the database via SQLi, an attacker can log in and leverage an arbitrary file upload vulnerability to obtain remote code execution.
CVE-2021-45040 1 Spatie 1 Laravel Media Library 2026-06-17 10.0 HIGH 9.8 CRITICAL
The Spatie media-library-pro library through 1.17.10 and 2.x through 2.1.6 for Laravel allows remote attackers to upload executable files via the uploads route.
CVE-2021-44967 1 Limesurvey 1 Limesurvey 2026-06-17 9.0 HIGH 8.8 HIGH
A Remote Code Execution (RCE) vulnerabilty exists in LimeSurvey 5.2.4 via the upload and install plugins function, which could let a remote malicious user upload an arbitrary PHP code file. NOTE: the Supplier's position is that plugins intentionally can contain arbitrary PHP code, and can only be installed by a superadmin, and therefore the security model is not violated by this finding.
CVE-2021-44673 1 Croogo 1 Croogo 2026-06-17 6.5 MEDIUM 8.8 HIGH
A Remote Code Execution (RCE) vulnerability exists in Croogo 3.0.2via admin/file-manager/attachments, which lets a malicoius user upload a web shell script.
CVE-2021-44664 1 Xerte 1 Xerte 2026-06-17 6.5 MEDIUM 8.8 HIGH
An Authenticated Remote Code Exection (RCE) vulnerability exists in Xerte through 3.9 in website_code/php/import/fileupload.php by uploading a maliciously crafted PHP file though the project interface disguised as a language file to bypasses the upload filters. Attackers can manipulate the files destination by abusing path traversal in the 'mediapath' variable.
CVE-2021-44651 1 Zohocorp 2 Log360, Manageengine Cloud Security Plus 2026-06-17 6.5 MEDIUM 8.8 HIGH
Zoho ManageEngine CloudSecurityPlus before Build 4117 allows remote code execution through the updatePersonalizeSettings component due to an improper security patch for CVE-2021-40175.
CVE-2021-44426 1 Anydesk 1 Anydesk 2026-06-17 N/A 8.8 HIGH
An issue was discovered in AnyDesk before 6.2.6 and 6.3.x before 6.3.5. An upload of an arbitrary file to a victim's local ~/Downloads/ directory is possible if the victim is using the AnyDesk Windows client to connect to a remote machine, if an attacker is also connected remotely with AnyDesk to the same remote machine. The upload is done without any approval or action taken by the victim.
CVE-2021-44164 1 Chinasea 1 Qb Smart Service Robot 2026-06-17 7.5 HIGH 9.8 CRITICAL
Chain Sea ai chatbot system’s file upload function has insufficient filtering for special characters in URLs, which allows a remote attacker to by-pass file type validation, upload malicious script and execute arbitrary code without authentication, in order to take control of the system or terminate service.
CVE-2021-44159 1 4mosan 1 Gcb Doctor 2026-06-17 10.0 HIGH 9.8 CRITICAL
4MOSAn GCB Doctor’s file upload function has improper user privilege control. A remote attacker can upload arbitrary files including webshell files without authentication and execute arbitrary code in order to perform arbitrary system operations or deny of service attack.
CVE-2021-44123 1 Spip 1 Spip 2026-06-17 6.5 MEDIUM 8.8 HIGH
SPIP 4.0.0 is affected by a remote command execution vulnerability. To exploit the vulnerability, an attacker must craft a malicious picture with a double extension, upload it and then click on it to execute it.
CVE-2021-44094 1 Zrlog 1 Zrlog 2026-06-17 6.8 MEDIUM 7.8 HIGH
ZrLog 2.2.2 has a remote command execution vulnerability at plugin download function, it could execute any JAR file
CVE-2021-44093 1 Zrlog 1 Zrlog 2026-06-17 7.5 HIGH 9.8 CRITICAL
A Remote Command Execution vulnerability on the background in zrlog 2.2.2, at the upload avatar function, could bypass the original limit, upload the JSP file to get a WebShell
CVE-2021-44031 1 Quest 1 Kace Desktop Authority 2026-06-17 7.5 HIGH 9.8 CRITICAL
An issue was discovered in Quest KACE Desktop Authority before 11.2. /dacomponentui/profiles/profileitems/outlooksettings/Insertimage.aspx contains a vulnerability that could allow pre-authentication remote code execution. An attacker could upload a .ASP file to reside at /images/{GUID}/{filename}.